UNSOLVED

ATIR

updated

22 years ago

A

ATIR

23 Posts

0

50211

December 10th, 2004 06:00

AVG Resident virus popups

:smileymad: I have had this particular problem since the first part of Oct.(2004). Everytime I log on and go to homepage, I immediately receive virus popups from AVG Resident Shield such as: AE Collect? and Win32/Parite.It says to run AVG which I do and it either heals the virus or I move it to virus vault. Unfortunately, within maybe 10 minutes or so the same popup comes up again immediately after I just ran the AVG virus scan. Why do the viruses keep coming up so many times while online? Any help with this would be much appreciated.
Thanks in advance~  
  • Midnight Star

    4791 Posts

    885

    0

    Posted December 10th, 2004 07:00

    ATIR,

    First, start by going to www.trendmicro.com and click "Free Online Scan". It'll take a few minutes to download and install. When it's done, select all available drives, then click "Scan".

    Post back the results.

    Mike.
  • ATIR

    23 Posts

    885

    0

    Posted December 10th, 2004 17:00

    Mike..
    I was amazed at how many more files the "trendmicro" scanned. Only found one virus and I am so mad at myself because I didn't write down or clik to see info about the virus. I do appreciate so much your help!! Think I'll be uninstalling AVG, because it obviously isn't catching everything!
    Hopefully this took care of things.
    Again, thanks so much...
  • Midnight Star

    4791 Posts

    885

    0

    Posted December 10th, 2004 17:00

    ATIR,
     
    Your more than welcome, but we need to look more closely - there could be other 'problems' lurking about still.
     
    Download HiJackThis, unzip it, then click " Scan", then " Save log" (same button). When Notepad comes up with a log for your computer, select all the text, and copy/paste it back to this thread. We'll use that to see if there's more; it's best to be safe. Don't try to 'fix' anything with it just yet, as most of what it will report is 'good'. Close both Notepad and HijackThis.
     
    AVG, Norton's and Symantec among just a few, usually do miss something that the other one will pick up. There's still a few more programs that we might need to download, but first, let's take a look at your system log.
     
    Mike.
     
  • ATIR

    23 Posts

    885

    0

    Posted December 11th, 2004 01:00

    Logfile of HijackThis v1.98.2
    Scan saved at 9:07:38 PM, on 12/10/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
    C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
    C:\Documents and Settings\Rita\My Documents\My Music\iTunesHelper.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\Program Files\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
    C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
    C:\snd.exe
    C:\Program Files\Windows AdControl\WinAdCtl.exe
    C:\Program Files\Windows AdControl\WinAdAlt.exe
    C:\windows\system32\rk.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\WinMX\WinMX.exe
    C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
    C:\Program Files\Exif Launcher\QuickDCF.exe
    C:\Program Files\CallWave\IAM.exe
    C:\Program Files\Web_Rebates\WebRebates1.exe
    C:\Program Files\EarthLink TotalAccess\FastLane\IPClient.exe
    C:\Program Files\EarthLink TotalAccess\Accelerator\ElinkAcc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Web_Rebates\WebRebates0.exe
    C:\DOCUME~1\Rita\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
    R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: (no name) - ~00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\6.bin\MWSSRCAS.DLL
    O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
    O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\6.bin\MWSBAR.DLL
    O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: (no name) - {EA78DBF8-C669-4093-4A03-672AC177C848} - C:\PROGRA~1\CURBEG~1\Bags Software.exe (file missing)
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O3 - Toolbar: EarthLink Toolbar - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O3 - Toolbar: &My Way Speedbar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
    O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
    O4 - HKLM\..\Run: [iTunesHelper] C:\Documents and Settings\Rita\My Documents\My Music\iTunesHelper.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [gwsrhathjgk] C:\WINDOWS\System32\etogqke.exe
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
    O4 - HKLM\..\Run: [does hole pure loud] C:\Documents and Settings\All Users\Application Data\FaceBoltDoesHole\DupeOkay.exe
    O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
    O4 - HKLM\..\Run: [MSNMaSRR5] MSNMaSGRS.exe
    O4 - HKLM\..\Run: [WIN32SNDAX] C:\snd.exe
    O4 - HKLM\..\Run: [Windows AdControl] C:\Program Files\Windows AdControl\WinAdCtl.exe
    O4 - HKLM\..\Run: [OSS] c:\windows\system32\rk.exe -boot
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\RunServices: [MSNMaSRR5] MSNMaSGRS.exe
    O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [WinMX] C:\Program Files\WinMX\WinMX.exe -m
    O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
    O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE
    O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
    O4 - Global Startup: Internet Answering Machine.lnk = C:\Program Files\CallWave\IAM.exe
    O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZC
    O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-page.html
    O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-image.html
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
    O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=21a47cb4fd3122a6c3b1f5580f17b8b59065ba8dc993db3650e231915933b4ea0ae75250a6014043e7ea5e6e4a7fc4049f20ee666f814bce72fdad330c01fc0bc3:631cd4669b71c6b0897750224652ac34
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/MySignatureFWBInitialSetup1.0.0.8.cab
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {72770C4F-967D-4517-982B-92D6B9015649} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/controls/DigWebX.cab?9,0,712,0
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {79B96C72-C0D0-4DC8-BC7E-9F314A918228} - http://ak.imgfarm.com/images/nocache/myspeedbar/myinitialsetup1.0.0.7.cab
    O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1437/ftp.coupons.com/v3123/cpbrkpie.cab
    O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
    O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocx
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4346BABD-6B8C-472D-AFDB-EE0CC45E03FF}: NameServer = 207.69.188.185 207.69.188.186
    O17 - HKLM\System\CS2\Services\Tcpip\..\{4346BABD-6B8C-472D-AFDB-EE0CC45E03FF}: NameServer = 207.69.188.185 207.69.188.186

     

  • Midnight Star

    4791 Posts

    886

    0

    Posted December 11th, 2004 07:00

    ATIR,

    And boy did it have friends!

    Ok, let's enlist the help of some free programs and see what they can do for us. You'll need to save this webpage to your harddrive for reference, since we're going to be rebooting your computer into a mode where the internet isn't available, or just print it out.

    If you have any questions before you begin, don't hesitate to post back.


    Let's download two free tools that when we're completely done cleaning off your pc, you'll be able to use on a regular basis to help keep your computer 'tidy'.

    • Download and install AdAware SE Personal; be sure to "Check for updates now", then exit the program (we're going to run it later).
    • Download and install Spybot S&D; be sure to "Search for Updates", download any that are available, then exit the program (we're going to run it later).

     

    Reboot your computer into "Safe Mode"


     
    Now, let's run the two free programs we've downloaded from above step, to help us remove some of that 'junk', one at a time...
     
    • Run AdAware SE Personal, then click "Start", then check(tick) "perform a full system scan", then click "Next". Allow it to remove all that it finds.
    • Run Spybot S&D, then click "Check for Problems". Allow it to remove all tht it finds.
     

    Next, go to Add/Remove programs, and remove the following, if present:

    • Windows AdControl
    • WebRebates
    • MyWebSearch
    • MyBar
    • MySearchBar

     

    Reboot your computer normally.


    Post back a new log, and let's see what we've got.

    Mike.

     

    Message Edited by Midnight Star on 12-11-2004 03:45 AM

  • ATIR

    23 Posts

    886

    0

    Posted December 12th, 2004 01:00

    :smileyhappy:Mike..just wanted to be sure and let you know I'm working on it. I've done the scanning, rebooting, scanning and removing problems with ADWareSE and SpyBot. Now I'm going to remove from the Add/Remove program. I will keep you informed on my progress. Thank you~

    Atir

  • Midnight Star

    4791 Posts

    886

    0

    Posted December 12th, 2004 05:00

    ATIR,
     
    I know. There was so much on that system, that there's almost no way of getting it off in one pass. Let's see what we have left. Go ahead and post up a new log and let me look it over.
     
    Hang in there.
     
    Mike.
     
  • ATIR

    23 Posts

    886

    0

    Posted December 12th, 2004 05:00

    Definitions File Loaded:

    Reference Number : SE1R21 03.12.2004

    Internal build : 26

    File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref

    File size : 407954 Bytes

    Total size : 1292266 Bytes

    Signature data size : 1262795 Bytes

    Reference data size : 28959 Bytes

    Signatures total : 35914

    Fingerprints total : 577

    Fingerprints size : 21902 Bytes

    Target categories : 15

    Target families : 625

    Mike..wasn't sure if this would be any help. If not, let me know how to proceed. Sorry it's such a long page. I'm still getting the AVG popups..darn!

    Thanks~

    Target families : 625ArchiveData(auto-quarantine- 2004-12-11 22-47-59.bckp)
    Referencefile : SE1R21 03.12.2004
    ======================================================
    MRU LIST
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    obj[0]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\applets\wordpad\recent file list
    obj[1]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\applets\paint\recent file list
    obj[2]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\runmru
    obj[3]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\search assistant\acmru\5001
    obj[4]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
    obj[5]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\AAC
    obj:emotion-14:=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.blg
    obj[7]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.bmp
    obj:emotion-29:=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.css
    obj[9]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.eml
    obj[10]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.gif
    obj[11]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.hlp
    obj[12]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.htm
    obj[13]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.inf
    obj[14]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.itl
    obj[15]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.jpg
    obj[16]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.js
    obj[17]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.LOG
    obj[18]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.m3u
    obj[19]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.m4a
    obj[20]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.mp3
    obj[21]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.pdf
    obj[22]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.png
    obj[23]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.pps
    obj[24]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.rtf
    obj[25]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.theme
    obj[26]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.txt
    obj[27]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.wav
    obj[28]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.wma
    obj[29]=MRU FileReference : C:\Documents and Settings\Rita\recent\05 How Far.lnk
    obj[30]=MRU FileReference : C:\Documents and Settings\Rita\recent\08-16-2004 10;22;50AM.lnk
    obj[31]=MRU FileReference : C:\Documents and Settings\Rita\recent\11-18-2004 10;13;08PM.lnk
    obj[32]=MRU FileReference : C:\Documents and Settings\Rita\recent\2004-01-26, Mom and Dad (Baker) Jan 2004.lnk
    obj[33]=MRU FileReference : C:\Documents and Settings\Rita\recent\48D3M-thumb-N08004-91.lnk
    obj[34]=MRU FileReference : C:\Documents and Settings\Rita\recent\48D5V-smaller-N08004-156.lnk
    obj[35]=MRU FileReference : C:\Documents and Settings\Rita\recent\6.bin.lnk
    obj[36]=MRU FileReference : C:\Documents and Settings\Rita\recent\Aaron Neville & Linda Ronstadt - I Don't Know Much.lnk
    obj[37]=MRU FileReference : C:\Documents and Settings\Rita\recent\Acknowledgements.lnk
    obj[38]=MRU FileReference : C:\Documents and Settings\Rita\recent\aleabanr.lnk
    obj[39]=MRU FileReference : C:\Documents and Settings\Rita\recent\amaizrul.lnk
    obj[40]=MRU FileReference : C:\Documents and Settings\Rita\recent\Amerie All I Have 10 Show Me.lnk
    obj[41]=MRU FileReference : C:\Documents and Settings\Rita\recent\Amy and Jenna.lnk
    obj[42]=MRU FileReference : C:\Documents and Settings\Rita\recent\Andrew & Miciah Hagan (pegs grandsons).lnk
    obj[43]=MRU FileReference : C:\Documents and Settings\Rita\recent\August 2004.lnk
    obj[44]=MRU FileReference : C:\Documents and Settings\Rita\recent\AUTORUN.lnk
    obj[45]=MRU FileReference : C:\Documents and Settings\Rita\recent\AVG6.lnk
    obj[46]=MRU FileReference : C:\Documents and Settings\Rita\recent\Avrll Lavigne-Dont Tell Me.lnk
    obj[47]=MRU FileReference : C:\Documents and Settings\Rita\recent\Blood Sweat and Tears - Eli's Coming.lnk
    obj[48]=MRU FileReference : C:\Documents and Settings\Rita\recent\Btzhsepa.lnk
    obj[49]=MRU FileReference : C:\Documents and Settings\Rita\recent\Callie and Isa 005.lnk
    obj[50]=MRU FileReference : C:\Documents and Settings\Rita\recent\CD Drive.lnk
    obj[51]=MRU FileReference : C:\Documents and Settings\Rita\recent\Chely Wright - bumper of my SUV story.lnk
    obj[52]=MRU FileReference : C:\Documents and Settings\Rita\recent\chimes.lnk
    obj[53]=MRU FileReference : C:\Documents and Settings\Rita\recent\chord.lnk
    obj[54]=MRU FileReference : C:\Documents and Settings\Rita\recent\cirkel_bliksem.lnk
    obj[55]=MRU FileReference : C:\Documents and Settings\Rita\recent\Corys address.lnk
    obj[56]=MRU FileReference : C:\Documents and Settings\Rita\recent\Country Music - Emmy Lou Harris-Don Williams-Duets-If I Needed You.lnk
    obj[57]=MRU FileReference : C:\Documents and Settings\Rita\recent\DaD(1).wps.lnk
    obj[58]=MRU FileReference : C:\Documents and Settings\Rita\recent\Default Playlist.lnk
    obj[59]=MRU FileReference : C:\Documents and Settings\Rita\recent\Dell.lnk
    obj[60]=MRU FileReference : C:\Documents and Settings\Rita\recent\dellbutn.lnk
    obj[61]=MRU FileReference : C:\Documents and Settings\Rita\recent\Desktop.ini
    obj[62]=MRU FileReference : C:\Documents and Settings\Rita\recent\Digital Camera Photos.lnk
    obj[63]=MRU FileReference : C:\Documents and Settings\Rita\recent\ding.lnk
    obj[64]=MRU FileReference : C:\Documents and Settings\Rita\recent\Document.lnk
    obj[65]=MRU FileReference : C:\Documents and Settings\Rita\recent\DSCF0037.lnk
    obj[66]=MRU FileReference : C:\Documents and Settings\Rita\recent\Dusty Springfield - Wishin' And Hopin'(1).lnk
    obj[67]=MRU FileReference : C:\Documents and Settings\Rita\recent\English.lnk
    obj[68]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric & Sam.lnk
    obj[69]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 006.lnk
    obj[70]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 008.lnk
    obj[71]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 123rd Batallion 011.lnk
    obj[72]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 123rd Batallion 012.lnk
    obj[73]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 123th Batallion.lnk
    obj[74]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric.lnk
    obj[75]=MRU FileReference : C:\Documents and Settings\Rita\recent\errorlog.lnk
    obj[76]=MRU FileReference : C:\Documents and Settings\Rita\recent\F3BKGERR.lnk
    obj[77]=MRU FileReference : C:\Documents and Settings\Rita\recent\fieruled.lnk
    obj[78]=MRU FileReference : C:\Documents and Settings\Rita\recent\filelib (2).lnk
    obj[79]=MRU FileReference : C:\Documents and Settings\Rita\recent\filelib (3).lnk
    obj[80]=MRU FileReference : C:\Documents and Settings\Rita\recent\filelib.lnk
    obj[81]=MRU FileReference : C:\Documents and Settings\Rita\recent\FINAL_Winter_Pack_Readme.lnk
    obj[82]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 048.lnk
    obj[83]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 050.lnk
    obj[85]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 052.lnk
    obj[84]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 051.lnk
    obj[86]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 053.lnk
    obj[87]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 055.lnk
    obj[88]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix.lnk
    obj[89]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePixViewer.lnk
    obj[90]=MRU FileReference : C:\Documents and Settings\Rita\recent\FW Miciah part 2.lnk
    obj[91]=MRU FileReference : C:\Documents and Settings\Rita\recent\Glacier.lnk
    obj[92]=MRU FileReference : C:\Documents and Settings\Rita\recent\Gretchen Wilson - When I Think About Cheatin'.lnk
    obj[93]=MRU FileReference : C:\Documents and Settings\Rita\recent\hijackthis.lnk
    obj[94]=MRU FileReference : C:\Documents and Settings\Rita\recent\Hotbar (2).lnk
    obj[95]=MRU FileReference : C:\Documents and Settings\Rita\recent\Hotbar.lnk
    obj[96]=MRU FileReference : C:\Documents and Settings\Rita\recent\Hurricane Charley.lnk
    obj[97]=MRU FileReference : C:\Documents and Settings\Rita\recent\imesh.lnk
    obj[98]=MRU FileReference : C:\Documents and Settings\Rita\recent\incubus_3323@hotmail.com.lnk
    obj[99]=MRU FileReference : C:\Documents and Settings\Rita\recent\infupd.lnk
    obj[100]=MRU FileReference : C:\Documents and Settings\Rita\recent\insert[1].lnk
    obj[101]=MRU FileReference : C:\Documents and Settings\Rita\recent\INSTALL.lnk
    obj[102]=MRU FileReference : C:\Documents and Settings\Rita\recent\ISamples.lnk
    obj[103]=MRU FileReference : C:\Documents and Settings\Rita\recent\iTunes 4 Music Library.lnk
    obj[104]=MRU FileReference : C:\Documents and Settings\Rita\recent\iTunes Music Library.lnk
    obj[105]=MRU FileReference : C:\Documents and Settings\Rita\recent\Jenna 10-2004 (2).lnk
    obj[106]=MRU FileReference : C:\Documents and Settings\Rita\recent\Jenna and Callie.lnk
    obj[107]=MRU FileReference : C:\Documents and Settings\Rita\recent\Jenna October 2004.lnk
    obj[108]=MRU FileReference : C:\Documents and Settings\Rita\recent\Jenna Pre-School Pic 2004.lnk
    obj[109]=MRU FileReference : C:\Documents and Settings\Rita\recent\juggler.lnk
    obj[110]=MRU FileReference : C:\Documents and Settings\Rita\recent\Katie.lnk
    obj[111]=MRU FileReference : C:\Documents and Settings\Rita\recent\Lexmark X74-X75.lnk
    obj[112]=MRU FileReference : C:\Documents and Settings\Rita\recent\Library.lnk
    obj[113]=MRU FileReference : C:\Documents and Settings\Rita\recent\login[2].lnk
    obj[114]=MRU FileReference : C:\Documents and Settings\Rita\recent\lthtt[1].lnk
    obj[115]=MRU FileReference : C:\Documents and Settings\Rita\recent\lxbbvb.lnk
    obj[116]=MRU FileReference : C:\Documents and Settings\Rita\recent\Martina McBride -  How Far.lnk
    obj[117]=MRU FileReference : C:\Documents and Settings\Rita\recent\Martina.lnk
    obj[118]=MRU FileReference : C:\Documents and Settings\Rita\recent\Media.lnk
    obj[119]=MRU FileReference : C:\Documents and Settings\Rita\recent\mmdriver.lnk
    obj[120]=MRU FileReference : C:\Documents and Settings\Rita\recent\montesscarlo@hotmail.com.lnk
    obj[121]=MRU FileReference : C:\Documents and Settings\Rita\recent\msoe.lnk
    obj[122]=MRU FileReference : C:\Documents and Settings\Rita\recent\My Chat Logs.lnk
  • Midnight Star

    4791 Posts

    368

    0

    Posted December 12th, 2004 18:00

    ATIR,

    While your running those programs, post back a HiJackThis log, just like you did previously and i'll look that over at the same time.

    Some 'problems' could be persistant beyond AdAware and Spybot.

    Mike.

     

  • ATIR

    23 Posts

    886

    0

    Posted December 12th, 2004 18:00

    ArchiveData(AD-Aware SE.bckp)

    Referencefile : SE1R21 03.12.2004

    ======================================================

    BLAZEFIND

    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    obj[0]=RegValue : software\microsoft\windows\currentversion\run "Windows AdControl"

    obj[5]=File : C:\System Volume Information\_restore{B59D285F-D4E8-4F0B-8C15-ECAD980571E6}\RP238\A0139257.dll

    TRACKING COOKIE

    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    obj[1]=IECache Entry : Cookie:rita@questionmarket.com/

    obj[2]=IECache Entry : Cookie:rita@apmebf.com/

    obj[3]=IECache Entry : C:\Documents and Settings\Rita\Cookies\rita@apmebf[1].txt

    obj[4]=IECache Entry : C:\Documents and Settings\Rita\Cookies\rita@questionmarket[2].txt

     

    Hoping this is some more help to you...I'm going to run SpyBot again.